Change logs for libssh source package in Lucid

  • libssh (0.4.2-1ubuntu1.2) lucid-security; urgency=low
    
      * SECURITY UPDATE: denial of service via NULL dereference
        - debian/patches/CVE-2013-0176.patch: properly handle client that
          doesn't send a matching key in libssh/server.c.
        - CVE-2013-0176
     -- Marc Deslauriers <email address hidden>   Fri, 25 Jan 2013 14:06:26 -0500
  • libssh (0.4.2-1ubuntu1.1) lucid-security; urgency=low
    
      * SECURITY UPDATE: denial of service and possible code execution via
        multiple double free flaws
        - debian/patches/CVE-2012-4559.patch: properly do frees in
          libssh/agent.c, libssh/channels.c, libssh/sftp.c.
        - CVE-2012-4559
      * SECURITY UPDATE: denial of service and possible code execution via
        multiple invalid free flaws
        - debian/patches/CVE-2012-4561.patch: properly zero structs in
          libssh/keys.c.
        - CVE-2012-4561
      * SECURITY UPDATE: denial of service and possible code execution via
        multiple improper overflow checks
        - debian/patches/CVE-2012-4562.patch: do proper overflow checks in
          libssh/buffer.c, libssh/dh.c, libssh/string.c.
        - CVE-2012-4562
     -- Marc Deslauriers <email address hidden>   Thu, 22 Nov 2012 14:32:59 -0500
  • libssh (0.4.2-1ubuntu1) lucid; urgency=low
    
      * Merge with Debian testing, remaining change:
        - Include conflicts/replaces on previous package versions with old sonames
          (LP: #514110)
     -- Jonathan Thomas <email address hidden>   Mon, 12 Apr 2010 19:07:38 -0400
  • libssh (0.4.0-1ubuntu1) lucid; urgency=low
    
      * Merge with Debian:
        - Include conflict/replaces on previous package versions with old sonames
     -- Jonathan Thomas <email address hidden>   Sun, 13 Dec 2009 20:31:49 -0500
  • libssh (0.3.92-0ubuntu1) lucid; urgency=low
    
      * New upstream prerelease:
        - Bump library .so number in binary packages
        - Update .symbols file
     -- Jonathan Thomas <email address hidden>   Wed, 02 Dec 2009 09:19:22 -0500
  • libssh (0.3.4-2ubuntu1) karmic; urgency=low
    
      * Merge with Debian
      * Include conflict/replaces on previous package versions with old sonames
    
    libssh (0.3.4-2) unstable; urgency=low
    
      * debian/watch: Update the URL
      * debian/copyright: Add missing licence for some cmake/Modules files
    
    libssh (0.3.4-1) unstable; urgency=low
    
      * New upstream release (Closes: #467284).
        - Adjust build-deps and use cmake
        - Bump soname and adjust .symbols file
      * debian/control:
        - Use my debian.org address in Uploaders and takeover the package
          with Jean-Philippe permission
        - Use now official Vcs-* field
        - Use new Homepage field instead of old pseudo-field
        - Bump Standards-Version to 3.8.3 (no further changes)
        - Use debug section for -dbg package
        - Add ${misc:Depends} to please lintian
        - Remove duplicate section to please lintian
      * debian/libssh-2-doc.doc-base: Fix doc-base-uses-applications-section
      * Bump debhelper version to 7
      * debian/libssh-dev.install: do not install .la file and static
        library anymore
      * debian/libssh-3.lintian-overrides: Update override
      * debian/copyright: Update copyright file
      * debian/libssh-3.symbols: Add initial symbols file
    
     -- Jonathan Riddell <email address hidden>   Mon, 12 Oct 2009 16:42:36 +0100